← Search

George Kesidis

12 accepted papers

2026

Improving the Sensitivity of Backdoor Detectors via Class Subspace Orthogonalization

ICML 2026poster

Most post-training backdoor detection methods rely on attacked models exhibiting extreme outlier detection statistics for the target class of an attack, compared to non-target classes. However, these approaches may fail: (1) when some (non-target) classes are easily discriminable from all others, in…

Cited by 0SourceScholar
2024

Temporal-Distributed Backdoor Attack against Video Based Action Recognition

AAAI 2024technical

Deep neural networks (DNNs) have achieved tremendous success in various applications including video action recognition, yet remain vulnerable to backdoor attacks (Trojans). The backdoor-compromised model will mis-classify to the target class chosen by the attacker when a test instance (from a non-t…

Cited by 8SourcePDFScholar
2023

Training Set Cleansing of Backdoor Poisoning by Self-Supervised Representation Learning

ICASSP 2023accepted

A backdoor or Trojan attack is an important type of data poisoning attack against deep neural network (DNN) classifiers, wherein the training dataset is poisoned with a small number of samples that each possess the backdoor pattern (usually a pattern that is either imperceptible or innocuous) and wh…

Cited by 0SourceScholar
2022

Detecting Backdoor Attacks against Point Cloud Classifiers

ICASSP 2022accepted

Backdoor attacks (BA) are an emerging threat to deep neural network classifiers. A classifier being attacked will predict to the attacker’s target class when a test sample from a source class is embedded with the backdoor pattern (BP). Recently, the first BA against point cloud (PC) classifiers was…

Cited by 0SourceScholar
2022

Post-Training Detection of Backdoor Attacks for Two-Class and Multi-Attack Scenarios

ICLR 2022poster

Backdoor attacks (BAs) are an emerging threat to deep neural network classifiers. A victim classifier will predict to an attacker-desired target class whenever a test sample is embedded with the same backdoor pattern (BP) that was used to poison the classifier's training set. Detecting whether a cla…

2022

Test-Time Detection of Backdoor Triggers for Poisoned Deep Neural Networks

ICASSP 2022accepted

Backdoor (Trojan) attacks are emerging threats against deep neural networks (DNN). A DNN being attacked will predict to an attacker-desired target class whenever a test sample from any source class is embedded with a backdoor pattern, while correctly classifying clean (attack-free) test samples. Exi…

Cited by 0SourceScholar
2021

A Backdoor Attack Against 3D Point Cloud Classifiers

ICCV 2021poster

Vulnerability of 3D point cloud (PC) classifiers has become a grave concern due to the popularity of 3D sensors in safety-critical applications. Existing adversarial attacks against 3D PC classifiers are all test-time evasion (TTE) attacks that aim to induce test-time misclassifications using knowle…

Cited by 94PDFcodeScholar
2021

L-Red: Efficient Post-Training Detection of Imperceptible Backdoor Attacks Without Access to the Training Set

ICASSP 2021accepted

Backdoor attacks (BAs) are an emerging form of adversarial attack typically against deep neural network image classifiers. The attacker aims to have the classifier learn to classify to a target class when test images from one or more source classes contain a backdoor pattern, while maintaining high…

Cited by 0SourceScholar
2020

Revealing Backdoors, Post-Training, in DNN Classifiers via Novel Inference on Optimized Perturbations Inducing Group Misclassification

ICASSP 2020accepted

Recently, a special type of data poisoning (DP) attack against deep neural network (DNN) classifiers, known as a backdoor, was proposed. These attacks do not seek to degrade classification accuracy, but rather to have the classifier learn to classify to a target class whenever the backdoor pattern i…

Cited by 0SourceScholar
2019

When Not to Classify: Detection of Reverse Engineering Attacks on DNN Image Classifiers

ICASSP 2019accepted

This paper addresses detection of a reverse engineering (RE) attack targeting a deep neural network (DNN) image classifier; by querying, RE's aim is to discover the classifier's decision rule. RE can enable test-time evasion attacks, which require knowledge of the classifier. Recently, we proposed a…

Cited by 0SourceScholar